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NON MALLEABLE ENCRYPTION APPARATUS AND METHOD 



Claim for Priority 

The present application is a continuation in part of parent application serial number 
09/237,522 which was filed on January 27, 1999 and claims the priority of said parent application. 
The parent application was pending at the time of filing of the present continuation in part 
application. 

Field of the Invention 

This invention relates to improved methods and apparatus for encryption and decryption of 

data. 

Background of the Invention 

The present invention deals with the area of encryption and decryption of data messages. 
Encryption takes a cleartext message and produces an encrypted message also called a 
ciphertext Decryption takes an encrypted message and produces its corresponding cleartext 
message. 
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It is known in the prior art how to take a message and turn it into an encrypted message 
using a first user's public key. The first user upon receiving the encrypted message can then 
decrypt it, to reveal the original message, using the first user's secret key. The first user's public 
key is as the name implies, available to the public so that others can send messages to the first 
user. However, the first user's secret key is not available. The public key is associated with a 
one-way function, i.e. once the message is encrypted it cannot be decrypted without the secret 
key even though the public key and the encryption algorithms are known. 

El Gamal encryption is a standard method of encryption known in the art. In this method a 
first processor performing the encryption step, takes a message m as an input; chooses a random 
value "c", and produces the outputs a = m*y c modulo p; b = g° modulo p. For El Gamal 
decryption, a second processor (which may be the first processor) calculates the data message m 
from m = a/b x modulo p. In the above y = g x modulo p is the public key and x is the secret key. 
The parameters g, x, and p and other system parameters are picked according to methods known 
to a person skilled in the art. The parameter g is a generator of the group G p . If we take all 
possible values of x and compute g x , this result will take all values in the group G p which is a large 
set of values. The value c is chosen at random by the entity that performs the encryption. 
The EIGamal encryption method has the following weaknesses: 

(1) Given an encryption (a,b) of an unknown data message m, 

it is possible to produce an encryption of a still unknown message, which 
corresponds to the value dm, by computing (a d modulo p, b). For 
example, if (a,b) is an encryption of the value m = 3, then (a',b') = (4a,b) is 
an encryption of the value 4m = 12. It is not necessary to know m to 
compute (a',b') from (a,b). 



Jakobsson 13-1 



(2) 



Given the encryption pair or ciphertext (a,b) of data 
message m, it is possible to produce a ciphertext of m d as (a d modulo p, b d ). 
For example, a correct message could be raised to some exponent and 



there would be no way of telling that that had occurred. 



(3) 



Given two ciphertexts (a1, b1) and (a2, b2), with (a1, b1) 



being an encryption of ml and (a2, b2) being an encryption of m2, it is 
possible to produce a ciphertext of the product of m1*m2 modulo p as 
(a1*a2 modulo p, b1*b2 modulo p). 
These three disadvantages and other and related ones are referred to in literature as 
malleability. Malleability is a threat to security, correctness of decryption of a message, and 
privacy in many situations. For example in an auction scenario if an offer for a product by a first 
individual is m, given the ciphertext a second individual can overbid and make his offer 2*m 
without knowing how much "m" is but knowing that the second individual will win the bidding 
process. Using a similar attack one can duplicate votes in an election to determine (later when all 
votes are decrypted) what you voted (by looking for a duplicate). In the prior art malleability is 
avoided by forcing the value of the data message m to be encrypted to be of a particular form, 
such as to always end in a particular string of length approximately 100 bits. This technique of 
avoiding malleability has two disadvantages: 

(a) First, it is not possible to determine that an encrypted message is of the 



valid form without decrypting it. 



(b) 



Secondly, this is not known to result in a problem-free system (i.e. a 'non- 



malleable encryption') and cannot be proved to result in a non-malleable 



encryption. 
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However, prior to the parent application there were no approaches better at dealing with 
the malleability problem without losing efficiency of the resulting scheme and ciphertext. 

The parent application provides a non-malleable encryption method where an encryption 
technique and a signing technique are used. An encryption processor takes a data message and 
produces an encryption using an encryption process. The encryption may also be called a 
ciphertext and typically would be comprised of first and second ciphertext portions. A signing 
processor takes the encryption and adds a signature to the first and second ciphertext portions 
using, for example, the second ciphertext portion as the public key for the signature. A receiver 
processor receives the ciphertext and the signature, decrypts the ciphertext to form a first data 
message, and determines if the first data message is valid by verifying the signature. 

The encryption processor of the parent application may employ EIGamal encryption for the 
encryption process to form the encryption. The signing processor may perform a Schnorr 
signature process for the signing process or any other similar discrete log based signature, as 
appreciated by those skilled in the art. The signing processor may use part of the encryption 
process to perform the signing process. 

Summary of the Invention 

The present invention provides an improvement over the parent application. The 
improvement is particularly useful for long data message lengths. The present invention also 
uses an encryption technique and a signing technique to provide a non-malleable encryption. An 
encryption processor takes a data message and produces an encryption using an encryption 
process. The result of the encryption may also be called a ciphertext. However, unlike the parent 
application, in an embodiment of the present invention, the ciphertext typically would be 
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comprised of first, second, and third portions. This ciphertext could be of the form of: (a new , b new , 
E). A signing processor takes the encryption and adds a signature s new to form a quadruplet of 

first, second, third, and fourth portions in the form of: (a new , b new , s new , E). A receiver processor 

receives the quadruplet, decrypts the ciphertext to form a first data message, and determines if 
the first data message is valid by verifying the signature. 

The encryption processor may employ EIGamal encryption for the encryption process to 

form the three portions of the ciphertext (a new , b new , E). The signing processor may perform a 

Schnorr signature process for the signing process or any other similar discrete log based 
signature, as appreciated by those skilled in the art. The signing processor may use part of the 
encryption process to perform the signing process. 

The above fast encryption method of is particularly useful for long message lengths. A 
message m can be encrypted using a transmitter secret key z to form a quantity E. A 

transmitter processor prepares a ciphertext quadruplet (a new , b new ,s new> E) where: 
a new = z * y° modulo p ; 
b new = g C modulop; 

s new " signature c ( a new> b new> E ) 

As in the parent application, y = g x modulo p is the public key and x is the receiver secret 
key. The parameters g, x, and p according to methods known to a person skilled in the art and 
the parameter g is a generator of the group G p . The parameter c is a random number. The 
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transmitter processor sends the ciphertext quadruplet (a new , b new ,s new , E) to a receiver 

processor. The receiver processor verifies the signature on s new using methods known in the 

art. The receiver processor then decrypts a new and b new using the receiver secret key x to get 

the transmitter secret key z, i.e. in the following manner: z = a new /b new x The receiver 
processor uses the transmitter secret key k to decrypt E to get the message M. 

Brief Description of the Drawings 

Fig. 1 shows a diagram of an apparatus in accordance with a first embodiment of the 
parent application; 

Fig. 2 shows a flow chart of a method in accordance with an embodiment of the parent 
application; and 

Fig. 3 shows a diagram of a transmitter processor and a receiver processor in accordance 
with an embodiment of the present invention; and 

Fig. 4 shows a flow chart of a method in accordance with another embodiment of the 
present invention. 

Detailed Description of the Drawings 

The embodiment of the parent application will be described with reference to Figs. 1 and 
2. In the parent application in one embodiment an apparatus comprising an encryption processor 
and a signing processor is provided. These processors may in fact be part of the same personal 
computer. For some purposes the encryption processor and signing processor may need to be 
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one and the same processor. For example, there are two parts of the standard El Gamat 
ciphertext, but these share the same value 'c', and so, the value "c" would be known by both the 
encryption processor and the signing processor. In fact the encryption processor and the signing 
processor may all need to be part of one and the same processor in some situations. The 
signature part may also use the value of c, and therefore, at least for the above example, needs to 
be part of the same processor or party. 

Fig. 1 shows an apparatus 10 comprised of an encryption processor 12 and a signing 
processor 16. The signing processor is connected to a receiver processor 18. The processors 12 
and 16 may actually be part of a single processor which may be a personal computer. The 
receiver processor 18 typically would be a separate personal computer but may also be part of the 
same personal computer. 

In the apparatus 10 the encryption processor 12 has an input port 12a. The encryption 
processor 12 is also connected to the signing processor 16 via communications link 12b. 
Communications link 12b, and the other communications links mentioned herein, may be any 
apparatus for linking computers or circuitry such as a port connected to another port by a wire or a 
fiber. The signing processor 16 is connected to the receiver processor 18 via communications link 
16a. The receiver processor 18 has an output port 18a. The encryption processor 12 is also 
connected to the signing processor 16 via port communications link 16b. It should be noted that 
one or more or all of the encryption processor 12, signing processor 16, and receiver processor 
18 may be implemented in a single processor through a single piece of computer software. 

The operation of the apparatus 10 of Fig. 1 is as follows and is also shown in part in the 
flow chart 100 of Fig. 2. A plaintext message "m" is sent to the input port 12a of encryption 
processor 12. The plaintext message may be a digital data message, which may be comprised of 
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a plurality of digital data bits or signals. The message "m" is encrypted by the encryption 
processor 12 using a method such as EIGamal encryption or some other known encryption 
process. The encryption pair or encryption (a,b) is produced on communications link 12b and 
sent to the signing processor 16. The encryption process performed by the encryption processor 
12 is shown in steps 102, 104, and 106 of Fig. 2. As shown in Fig. 2 for the input message "m", a 
random number "c" is first generated at step 102. The random number "c" is used to calculate the 
quantity a = m*y c modulo p and the quantity b = g c modulo p at the steps 104 and 106 in Fig. 2. 
The value "c" in this example would be in the range of 0 <= c <= q; where q is the size of G p . 

The encryption pair (a,b) is sent to the signing processor 16. The random number c is 
also sent to the signing processor 16 from the encryption processor 12 via the communications 
link 16b At step 108 of Fig. 2, the signing processor 16 uses the random number 'c' which was 
chosen for the encryption process by encryption processor 12, to obtain a signature "s". The 
signing processor 16 may then execute step 110 of Fig. 2 by outputting the triplet (a,b,s) to the 
receiver processor 18. 

The value for the signature "s" can be obtained for example by using the Schnorr signature 
scheme. For that scheme the following steps are followed: 

(1 ) a random value k is picked where 1 <= k <= q; 

(2) r=g k modulo p is computed; 

(3) o= k - x h(M,r) mod q is computed; 

where h () denotes a so-called hash function; and M = (a,b) is the message to be signed. 

(4) Output the signature (r, a) which is what we call the signature "s"; 

The receiver processor 18 may use the input of (M, r, a) in order to verify the signature 
and thus verify that the decrypted message is a decryption of a valid data message by verifying if 
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r =gay h ( mr ) modulo p. The above signature generation and verification is well known to those 
skilled in the art. 

The signature "s" is appended to the encryption pair (a, b) to form the triplet (a,b,s) and 
this is output on communications link 16a, as shown by step 1 10 in Fig. 2. This triplet is received 
at the receiver processor 18. The receiver processor 18 can then decrypt the encryption pair (a,b) 
to obtain the original message m by calculating m = (a/b) x ; where x is the secret decryption key of 
a user. The receiver processor 18 can also use the value "b" as a public key to determine if the 
triplet (a,b,s) is valid or not tampered with. 

Encryption methods, other than EIGamal can be used, particularly variations of EIGamal. 
Signature methods other than Schnorr can be used such as Digital Signature Standard 
(hereinafter "DSS") which is a U.S. signature standard. Instead of a signature method, a proof-of- 
discrete-log system can be used. Several such methods are well known in the literature. 
The Schnorr signature process uses one or both portions (a, b) of the standard EIGamal 
encryption as a public key, most likely just the portion 'b' of the standard EIGamal encryption and 
the corresponding secret portion (the random number 'c' above), to sign a message. A signature 
's' is provided with the encrypted message. The signature 's' is a function of the encrypted 
message (a, b), potentially including publicly available information, such as the time or date. It 
can be publicly verified by anybody who gets the ciphertext, but can only be generated by a party 
with knowledge of the secret random number "c" used for encryption used for encryption. In the 
example referred to, the signer's secret key is based on the random number "c" which is used by 
the entity or processor, such as encryption processor 12, which encrypts a message, such as 
message "m", and said encryption processor also preferably functions as a signing processor 16 
which computes the ciphertext (a,b,s). The overall encryption data is now a triplet of (a,b,s). In 
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this case (a,b) or portions thereof act as the public key, (a,b) or a function thereof is the message 
and "s" is the signature. The ciphertext (referring to (a,b, and s)) is said to be valid if "s" is the 
signature on (a,b) with respect to the chosen public key (which is (a,b, or functions of these)). 

This new encryption method can be proved to be non-malleable, i.e. given some number 
of ciphertexts (a„ b h Sj), it is impossible to produce a new or valid ciphertext from the old 
ciphertexts, or a new and valid ciphertext with a plaintext message in any known way related to 
the plaintext messages corresponding to the old ciphertexts. Furthermore, the validity of a 
ciphertext can be publicly verified in an efficient manner using our proposed methods and 
apparatus. It retains the property that given a ciphertext (a,b,s), and two potential plaintext 
messages ml and m2, it is impossible to determine which one corresponds to (a,b,s). The new 
ciphertext (a,b,s) as opposed to the old (a,b), is decrypted as before, i.e. by calculating 
m=a/b x modulo p after verifying that (a,b,s) is a valid ciphertext. The method described with 
reference to Figs. 1 and 2 is for the parent application. 

Fig. 3 shows a transmitter processor 200 and a receiver processor 202 employing a fast 
encryption method in accordance with an embodiment of the present invention. The method is 
shown in the flow chart 300 in Fig. 4. 

In accordance with the method shown by Figs. 3 and 4, a new quantity, "z" is used, "z" 
will be called the "transmitter secret key" and is thus a secret key only known to the transmitter 
processor 200. At step 302 the transmitter processor 200 takes a message m and encrypts it 
using the transmitter secret key z to form a quantity E. 

At step 304 the transmitter processor 200 prepares a quadruplet (a new , b new ,s new E) 

where: 

a new = z * y° modulo p ; 
b new = 9 C modulo p; 

10 



Jakobsson 13-1 

s new = signature c ( a new> b new> E ); 
E = encrypt z (m); 

s new = signature c ( a new> b new> E ) means that the entire quantity is signed. 

As in the previous embodiments y = g x modulo p is the public key and x is the 
receiver secret key. The parameters g, x, and p are selected according to methods known to a 
person skilled in the art and the parameter g is a generator of the group G p . In this embodiment, c 
is a random number and has a similar function as the random number "c" in the first embodiment. 
These parameters may be selected in accordance with El Gamal encryption. 

At step 306 the transmitter processor 200 sends the quadruplet (a new , b new ,s neWj E) to 
the receiver processor 202. 

At step 308 the receiver processor 202 verifies the signature on s new using methods 
known in the art. 

At step 31 0 the receiver processor 202 decrypts (a new , b new ) using the receiver secret 
key x to get the transmitter secret key z, i.e. in the following manner, z = a new /b new x modulo p. 

At step 312 the receiver processor 202 uses the transmitter secret key z to decrypt E to 
determine the message m. 

The transmitter processor 200 and receiver processor 202 may be personal computers 
which run computer software to implement the methods of the present invention and may be 
connected by a communications link such as communications link 200a. The transmitter 
processor 200 and receiver processor 202 may both have memory for storing intermediate or 
final data messages, ciphertexts, quadruplets, or other computer data signals as needed. 
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The last method is particularly advantageous for long data messages of many bits for 

"m". This is because y can be thought of as a "blanket" which is used to hide what it is 
multiplied by. Thus in the earlier embodiment y c was multiplied by the message m. However, 
in that case the message m could only be as many bits as y c or the message m wouldn't be 

hidden. Therefore in the earlier embodiment of the present invention, the message size of m 
was limited to the size of y c . 

However, in the embodiment of Figs. 3 and 4, y c was multiplied by z (the transmitter 
secret key) and thus z would be limited in size (i.e. no. of bits) to the number of bits for y c . 

However, m would not be limited at all in size. The message "m" is made available to the 
receiver processor by encrypting it using z to form E and transmitting E to the receiver 
processor 202. 

There may actually be a primary transmitter secret key z which can be chosen as, z = 
g Y modulo p, for a random value of y chosen from the set [0..q]. The value q is chosen in 

accordance with known encryption methods such as El Gamal encryption. If this primary 
transmitter key z is not of the format used for producing the ciphertext E (e.g. is of the wrong 
length) then a secondary temporary key z' can be computed as z' = f(z), where f is an abitrary 
but agreed upon function, such as truncation. In the setting relating to triple - DES ("Digital 
Encryption Standard"), for example, one would want the key z' used for encryption of m to form 
E to be of the form z 1 , z 2 such that z-, and z 2 are both 56 bit keys. The quantities z-, and z 2 can 
be called portion keys. In this example, the function would truncate the primary transmitter key 
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z to a length of 1 12 bits, and then divide the resulting secondary transmitter key z' into two 
equal-sized portions z 1 and z 2 , which can be done by letting z 1 be the first 56 bits of the 

secondary transmitter key z' and z 2 the remaining 56 bits. 

Instead of employing the mathematical operations (i.e. the exponentiation and 
multiplication shown) 

a new = z * y° modulo P ; 

b new = g C modulo p; 

s new = signature c (a newl b new ,E) 

mathematical operations may be employed using elliptical curves as known in the art. 
The substitution of elliptical curve mathematical operations in cryptography is shown by "Use of 
Elliptic Curves in Cryptography", copyright 1998, by Victor S. Miller, Exploratory Computer 
Science, IBM Research, P.O. Box 218, Yorktown Heights, N.Y. 10598.; and "Non Supersingular 
Elliptic Curves for Public Key Cryptosystems" by Beth, Schaefer, 1998 from the Institut for 
Algorithmen and Kogntive Syteme Universitat Karksruhe, Fasanengarten 5, D-7500 Kariruhe 1. 
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I claim: 

1 . A method comprising the steps of: 

encrypting a data message m using a primary transmitter secret key z to form a quantity 

E; 

preparing a quadruplet (a new , b new ,s new , E) where: 
a new = z * y° modulo p ; 
b new = 9 C modulo pj 
s new = signature c (a n ew. b new« E ); 

where y = g x modulo p, c is a random number, x is a receiver secret key, and the 

parameters g, x, and p are picked using a known encryption method; 

verifying the signature s new; 

decrypting a new and b new using the receiver secret key x to get the primary transmitter 
secret key z; 

using the primary transmitter secret key z to decrypt the quantity E and thereby 
obtaining the message m. 

2. The method of claim 1 and wherein: 

the step of decrypting a new and b new using the receiver secret key x to get the primary 

transmitter secret key z is comprised of computing z = a n ew /b new X • 
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3. The method of claim 1 wherein: 

El Gamal encryption is used for the encrypting steps. 

4. The method of claim 2 wherein: 

El Gamal encryption is used for the encrypting steps. 

5. The method of claim 1 wherein: 

the primary transmitter secret key z is determined from the formula of z = g Y modulo p 3 

where y is a random value chosen from the set [0..q], where q is a value picked using a known 
encryption method. 

6. A method comprising the steps of: 

creating a primary transmitter key z; 

creating a secondary transmitter key z' which is a function of z; 
encrypting a data message m using the secondary transmitter secret key z' to form a 
quantity E; 

preparing a quadruplet (a new , b new ,s new , E) where: 
a new = z * y° modulo p ; 
b new = g C modulop; 
s new = signature c ( a new b new> E ); 

where y = g x modulo p, c is a random number, x is a receiver secret key, and the 

parameters g, x, and p are picked using a known encryption method; 
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verifying the signature s new; 

decrypting a new and b new using the receiver secret key x to get the primary transmitter 
secret key z; 

modifying the primary transmitter secret key z to obtain the secondary transmitter 
secret key z' and using the secondary transmitter secret key z' to decrypt the quantity E and 
thereby obtaining the message m. 

7. The method of claim 6 and wherein: 

the primary transmitter key z is provided which is not of the format used for producing the 
ciphertext E; 

the secondary transmitter key z' is computed as a function of z, where the function is an 
arbitrary function. 

8. A method comprising the steps of: 

creating a primary transmitter key z; 

creating a secondary transmitter key z' which is a function of z; 

providing a plurality of portion keys which are derived from the secondary transmitter 

key z 5 ; 

encrypting a data message m using the plurality of portion keys to form a quantity E; 

preparing a quadruplet (a new , b neWJ s new , E) where: 
a new = z * y° modulo p ; 
b new = g° m °dulop; 
s new = signature c (a n ew^new.E); 
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where y = g x modulo p, c is a random number, x is a receiver secret key, and the 

parameters g, x, and p are picked using a known encryption method; 
verifying the signature s new; 

decrypting a new and b new using the receiver secret key x to get the primary transmitter 
secret key z; 

modifying the primary transmitter secret key z to obtain the secondary transmitter 
secret key z' and using the secondary transmitter secret key z' to determine the plurality of 
portion keys and using the plurality of portion keys to decrypt the quantity E and thereby 
obtaining the message m. 
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ABSTRACT 

A fast encryption method particularly useful for long message lengths is provided. A 
message m is encrypted using a transmitter secret key z to form a quantity E. A transmitter 
processor prepares a quadruplet (a new , b new ,s new , E) where: 

a new = z * y° modulo p ; 

b new = 9 C modulo p; 

s new = signature c (a n ew< b new> E )- 

As in previous embodiments y = g x modulo p is the public key and x is the receiver 
secret key. The parameters g, x, and p according to methods known to a person skilled in the art 
and the parameter g is a generator of the group G p . The parameter c is a random number. The 
transmitter processor sends the quadruplet (a new , b new ,s new , E) to a receiver processor. The 

receiver processor verifies the signature on s new using methods known in the art. The receiver 
processor then decrypts a new and b new using the receiver secret key x to get the transmitter 
secret key z, i.e. in the following manner, z = a new /b new x The receiver processor uses the 
transmitter secret key z to decrypt E to get the message M. 
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IN THE UNITED STATES 
PATENT AND TRADEMARK OFFICE 

Declaration and Power of Attorney 



As a below named inventor, I hereby declare that: 

My residence, post office address and citizenship are as stated below next to my name. 

I believe I am an original, first and (joint) inventor of the subject matter which is claimed 
and for which a patent is sought on the invention entitled NON MALLEABLE ENCRYPTION 
APPARATUS AND METHOD the specification of which is attached hereto.. 

I hereby state that I have reviewed and understand the contents of the above identified 
specification, including the claims, as amended by an amendment, if any, specifically referred to in 
this oath or declaration. 

I acknowledge the duty to disclose all information known to me which is material to 
patentability as defined in Title 37, Code of Federal Regulations, 1 .56. 

I hereby claim foreign priority benefits under Title 35, United States Code, 119 of any 
foreign application(s) for patent or inventor's certificate listed below and have also identified below 
any foreign application for patent or inventor's certificate having a filing date before that of the 
application on which priority is claimed: 

None 

I hereby claim the benefit under Title 35, United States Code, 120 of any United States 
application(s) listed below and, insofar as the subject matter of each of the claims of this application 
is not disclosed in the prior United States application in the manner provided by the first paragraph 
of Title 35, United States Code, 112, 1 acknowledge the duty to disclose all information known to 
me to be material to patentability as defined in Title 37, Code of Federal Regulations, 1.56 which 
became available between the filing date of the prior application and the national or PCT 
international filing date of this application: 



None 



I hereby declare that all statements made herein of my own knowledge are true and that all 
statements made on information and belief are believed to be true; and further that these statements 
were made with the knowledge that willful false statements and the like so made are punishable by 
fine or imprisonment, or both, under Section 1001 of Title 18 of the United States Code and that 
such willful false statements may jeopardize the validity of the application or any patent issued 
thereon. 
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I hereby appoint the following attorneys) with full power of substitution and revocation, to 
prosecute said application, to make alterations and amendments therein, to receive the patent, and to 
transact all business in the Patent and Trademark Office connected therewith: 

Lester H. Birnbaum (Reg. No. 25830) 

Richard J. Botos (Reg. No. 32016) 

Jeffrey J. Brosemer (Reg. No. 36096) 

Kenneth M. Brown (Reg. No. 37590) 

Donald P. Dinella (Reg. No. 39961) 

Guy Eriksen (Reg. No. 4 1 736) 

Martin I. Finston (Reg. No. 3 1 613) 

James H. Fox (Reg. No. 29379) 

William S. Francos (Reg. No. 38456) 

Barry H. Freedman (Reg. No. 26166) 

Julio A. Garceran (Reg. No. 37138) 

Mony R. Ghose (Reg. No. 38 1 59) 

Jimmy Goo (Reg. No. 36528) 

Anthony Grillo (Reg. No. 36535) 

Steven M. Gurey (Reg. No. 27336) 

John M. Harman (Reg. No. 38173) 

Donald E. Hayes Jr. (Reg. No. 33245) 

John W. Hayes (Reg. No. 33900) 

Michael B. Johannesen (Reg. No. 35557) 

Mark A. Kurisko (Reg. No. 3 8944) 

Irena Lager (Reg. No. 39260) 

Christopher N. Malvone (Reg. No. 34866) 

Scott W. McLellan (Reg. No. 30776) 

Martin G. Meder (Reg. No. 34674) 

Geraldine Monteleone (Reg. No. 40097) 

John C. Moran (Reg. No. 30782) 

Michael A. Morra (Reg. No. 28975) 

Gregory J. Murgia (Reg. No. 41209) 

Claude R. Narcisse (Reg. No. 38979) 

Joseph J. Opalach (Reg. No. 36229) 

Neil R. Ormos (Reg. No. 35309) 

Eugen E. Pacher (Reg. No. 29964) 

Jack R. Penrod (Reg. No. 3 1 864) 

Daniel J. Pitrowski (Reg. No. 42079) 

Gregory C. Ranieri (Reg. No. 29695) 

Scott J. Rittman (Reg. No. 390 1 0) 

Eugene J. Rosenthal (Reg. No. 36658) 

Bruce S. Schneider (Reg. No. 27949) 

Ronald D. Slusky (Reg. No. 26585) 

David L. Smith (Reg. No. 30592) 

Patricia A. Verlangieri (Reg. No. 4220 1 ) 

John P. Veschi (Reg. No. 39058) 

David Volejnicek (Reg. No. 293 55) 

Charles L. Warren (Reg. No. 27407) 

Eli Weiss (Reg. No. 17765) 
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I hereby appoint the attorney(s) on ATTACHMENT A as associate attorney's in the 
aforementioned application, with full power solely to prosecute said application, to make alterations 
and amendments therein, to receive the patent, and to transact all business in the Patent and 
Trademark Office connected with the prosecution of said application. No other powers are granted 
to such associate attorney's and such associate attorney's are specifically denied any power of 
substitution or revocation. 



Full name of 1st joini)imlprwDr: Bjorn Markus Jakobsson 

Inventor's signature rHjr\-- Date Dg-c ^ < 

Residence: 161 NewarkStreet #4A; Hudson County; 
Hoboken,N.J. 07030 

Citizenship: Sweden 

Post Office Address: 161 Newark Street #4A; Hudson County; 
Hoboken, N.J. 07030 



Full Name of 2 joint inventor: Claus Peter Schnorr 

Inventor's stature <T? < ^J~^ Date t^C- ^ , M S 

Residence: Frankfurter Strasse 81 

61231 BadNauheim, Germany 

Citizenship: Germany 

Post Office Address: Frankfurter Strasse 8 1 

61231 BadNauheim, Germany 
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ATTACHMENT A 

Attorney Name(s): Walter J. Tencza, Jr. Reg. No.: 35,708 

10 Station Place. Suite 3 

Metuchen. N.J. 08840 

Telephone calls should be made to Walter J. Tencza, Jr. at: 
Phone No.: (732) 549-3007 
Fax No.: (732) 549-8486 

All written communications are to be addressed to: 

Walter J. Tencza, Jr. 
10 Station Place, Suite 3 
Metuchen, N. J. 08840 
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